System and method for modeling and managing information security risks
Abstract
The system and method identifies and manages information security risks of existing information systems. The method includes obtaining and synthesizing information security and cybersecurity frameworks to obtain a normalized information security framework. The method also includes obtaining information on existing information systems. The method also includes generating, from the information, based on the normalized information security framework, and customer business context, a risk model that is structured to account for customers' information security ecosystem. The method also includes analyzing the risk model's graph structures to identify information security risk. The method also includes identifying and proposing prioritizing changes to the existing information systems to address the identified risk.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for identifying and addressing information security risks of existing information system, the method comprising:
obtaining a plurality of information security and cybersecurity frameworks: synthesizing the plurality of information security and cybersecurity frameworks to obtain a normalized information security framework; obtaining information on existing information systems; generating, from the information, based on the normalized information security framework and customer business context, a risk model that is structured to account for customers' information security ecosystem; analyzing the risk model's graph structures to identify information security risk; and identifying and proposing prioritizing changes to the existing information systems to attempt to address the identified risk.
2 . The method of claim 1 , wherein each information security and cybersecurity framework includes a taxonomy of risks, controls and/or assets.
3 . The method of claim 1 , wherein synthesizing the plurality of information security and cybersecurity frameworks uses predetermined libraries of categorizations and templates.
4 . The method of claim 1 , wherein synthesizing the plurality of information security and cybersecurity frameworks comprises addressing biases and variability across the plurality of information security and cybersecurity frameworks.
5 . The method of claim 1 , wherein the risk model comprises a multipartite graph comprising nodes representing risks, controls and/or assets, and edges representing relationships between the nodes.
6 . The method of claim 1 , wherein analyzing the risk model's graph structures comprises:
traversing the risk model's graph structures to identify risk entries for risk simulations; and populating information in the risk entries at least in part from a risk profile associated with the existing information systems.
7 . The method of claim 6 , wherein the risk profile is customizable by an operator of the existing information systems.
8 . The method of claim 6 , wherein the risk profile includes templated risk-profile likelihood parameters per risk categorization and per North American Industry Classification System (NAICS) categorization, wherein the risk-profile likelihood parameters are customizable per client context, and wherein data for the risk-profile likelihood parameters includes ranges for controls.
9 . The method of claim 1 , wherein a client's information security business context represented on a client model is populated with risk profile information associated with its existing information systems towards statistical analysis of risk.
10 . The method of claim 9 , wherein the statistical analysis comprises:
identifying one or more control sets that are most correlated to most significant risks; projecting the one or more control sets into a copy of the client model; and forecasting risk adjusted by the one or more control sets by reapplying one or more risk methods used to generate a risk forecast of the client model.
11 . The method of claim 9 , wherein the statistical analysis comprises:
generating risks from scoped portions of the client model; and aggregating, managing, and/or filtering lists of risks and their uncertain parameters, such as probabilities, duration ranges, and impact ranges.
12 . The method of claim 9 , wherein the statistical analysis comprises:
forecasting probabilities and financial impacts by repeatedly simulating over a multiplicity of uncertain outcomes occurring across complex systems.
13 . The method of claim 9 , wherein the statistical analysis comprises:
storing and reusing random outputs generated in simulations towards standardizing control projection comparison.
14 . The method of claim 9 , wherein the statistical analysis comprises:
performing a series of trials that simulates occurrence and impact of potential risk events; and for each trial, summarizing simulated loss occurrences.
15 . The method of claim 1 , wherein the information on the existing information systems is updated and/or obtained from one or more compliance audits or assessments of security risks for the existing information systems.
16 . The method of claim 1 , wherein results of a risk assessment are reconfigurable per predefined categories.
17 . The method of claim 1 , further comprising:
autogenerating risk events based on relationships between modelled asset and risk categorizations, wherein the risk categorizations are related to one or more asset categorizations.
18 . The method of claim 1 , further comprising:
adjusting a plurality of risk categorizations based on a single control categorization.
19 . The method of claim 1 , further comprising:
adjusting a single risk categorization based on a plurality of control categorizations, including handling residual risk likelihoods from adjacent controls using a weighted average mechanism.
20 . The method of claim 1 , further comprising:
adjusting risk categorizations based on layered control categorizations, including handling residual risk likelihoods from layered controls using a probability calculation that both controls occur.
21 . The method of claim 1 , further comprising:
adjusting one or more risk-profile parameters according to related controls, including decreasing generic risk-profile likelihood parameters based on quality of related control, mitigating impact parameters by insurance coverage, and mitigating event duration parameters by incident response.
22 . The method of claim 1 , further comprising:
providing interfaces to a client model and an associated risk profile, comprising:
scoping sections of the client model and the associated risk profile using templates that parameterize categories of the client model and the associated risk profile that are associated with a service;
providing evaluation guidelines or parameters using evaluation templates that define how to assess scoped categories; and
normalizing correlated information for translating equivalent evaluation results between disparate evaluation methodologies.
23 . The method of claim 1 , further comprising:
generating assessments for existing control framework standards based on results of assessments performed for other control framework standards.
24 . The method of claim 1 , further comprising:
generating an assessment of how different audits in an operator's context for the existing information system are related to one another.
25 . The method of claim 1 , further comprising:
interfacing with, and providing the risk model's graph and associated risk profile, to one or more services selected from the group consisting of: e-mail protection, managed detection and response, managed perimeter defense, Vulnerability Management as a Service (VMaaS), automation of patching assessment scoring from system coverage, patch level, and timeliness statistics, threat modeler including providing supplementary tactical threat intelligence information and context, and privacy practice assessment that layers onto and assesses an operator's privacy business context.
26 . The method of claim 1 , wherein identifying potential changes to the existing information system to address the identified risk comprises:
presenting the identified risk to an operator of the existing information systems, presenting risk remediation options, to enable them to make informed business decision on risk treatment investments.
27 . The method of claim 1 , further comprising:
generating and displaying a visualization of forecast for the identified risk in different representations, including comparison in relation to client risk tolerances.
28 . The method of claim 27 , wherein the visualization is presented on a per risk basis or a per risk subset basis.
29 . The method of claim 1 , wherein identifying potential changes to the existing information systems to address the identified risk comprises:
prioritizing information security initiatives corresponding to the identified risk.
30 . The method of claim 1 , wherein identifying potential changes to the existing information systems to address the identified risk comprises:
computing and displaying expenditures, annual loss expectancy, return on investment, based on control projections and cost estimations, and a comparison to other organization in a same industry as a client, for the identified risk.
31 . The method of claim 1 , wherein identifying potential changes to the existing information systems to address the identified risk comprises:
simulating how an outsourced service or project is likely to improve a client's information security posture with respect to the identified risk.
32 . A computer system for identifying and addressing information security risks of existing information system, the computer system comprising:
one or more processors; and memory; wherein the memory stores one or more programs configured for execution by the one or more processors, and the one or more programs comprising instructions for: obtaining a plurality of information security and cybersecurity frameworks; synthesizing the plurality of information security and cybersecurity frameworks to obtain a normalized information security framework; obtaining information on existing information systems; generating, from the information, based on the normalized information security framework and customer business context, a risk model that is structured to account for customers' information security ecosystem; analyzing the risk model's graph structures to identify information security risk; and identifying and proposing prioritizing changes to the existing information systems to attempt to address the identified risk.
33 . A non-transitory computer readable storage medium storing one or more programs configured for execution by a computer system having one or more processors, and memory, the one or more programs comprising instructions for:
obtaining a plurality of information security and cybersecurity frameworks; synthesizing the plurality of information security and cybersecurity frameworks to obtain a normalized information security framework; obtaining information on existing information systems; generating, from the information, based on the normalized information security framework and customer business context, a risk model that is structured to account for customers' information security ecosystem; analyzing the risk model's graph structures to identify information security risk; and identifying and proposing prioritizing changes to the existing information systems to attempt to address the identified risk.Join the waitlist — get patent alerts
Track US2025045666A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.